Data Processing Terms
This document is published in English. The English text is the binding version; any translation is provided for convenience. If you would prefer to review it in Arabic with your own counsel, write to support@menew.io and we will provide it.
In short
- Your diners' data is yours. You decide what happens to it; we only carry out instructions.
- We will not use it for our own purposes, will not sell it, and will not train AI models on it.
- It is stored in the EU (Frankfurt). Our sub-processors are listed, and we give notice before adding one.
- If there is a breach, you hear from us within 72 hours.
- When you leave, you get an export, and then we delete it.
This box is a summary. The sections below are the agreement.
These Data Processing Terms (the "DPT") apply whenever Menew processes personal data on behalf of a restaurant using the platform. They form part of the Terms of Service and are accepted with them. Where the two conflict on the handling of personal data, this document wins.
Contents
1. Roles
For personal data about your diners, your staff and your bookings, you are the controller and Menew is your processor. You decide why and how that data is processed; we act on your instructions.
For personal data about your account with us — your name, your email, your billing history — Menew is the controller, and the Privacy Policy governs it rather than this document.
2. Scope of processing
| Subject matter | Providing the Menew platform to your restaurant |
|---|---|
| Duration | For as long as your subscription runs, plus the deletion window in section 12 |
| Nature and purpose | Hosting, storing, transmitting and displaying your menu and your orders; operating your stations; sending transactional email you have configured; taking backups |
| Types of personal data | Diner name and phone number (delivery and pickup orders, reservations); delivery address; order contents and history; table display name; a random device identifier; reservation details; ratings and comments; staff names and hashed station PINs; device and browser hints for signed-in devices; audit-log entries |
| Categories of data subject | Your diners, your staff, and the people who book tables with you |
| Special category data | None is collected by the platform. A diner's dietary and allergy filters — which could be health data — are stored only in the diner's own browser and are never transmitted to Menew or to you. See section 6. |
3. Our instructions
We process personal data only:
- to provide the platform as described in the Terms of Service and configured by you;
- on your further documented instructions, where we agree to them; and
- where a law we are subject to requires it — in which case we will tell you before processing, unless that law forbids us from telling you.
We will not:
- sell, rent or share your diners' personal data with anyone, for any purpose;
- use it for our own marketing, or for the benefit of any other customer;
- use it to train, fine-tune or evaluate machine-learning models — ours or anyone else's. Where the console offers AI assistance for menu translation, nutrition estimates or photo suggestions, only the menu text needed for that task is sent, and no diner data is ever sent to an AI service;
- combine it with data from another restaurant.
If we consider an instruction of yours to breach applicable data-protection law, we will tell you and may decline it.
4. Confidentiality
Anyone we authorise to process your data is bound by a duty of confidentiality that survives the end of their engagement, and is given access only to what their role requires.
5. Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- Tenant isolation enforced in the database. Row-level security means one restaurant's credentials cannot read another's data — this is not merely hidden in the interface, and it is tested against the live platform every night.
- Encryption in transit (TLS) and at rest.
- Station PINs and printer secrets stored as bcrypt hashes, unreadable by us.
- Station tokens generated from a cryptographic random source, rotatable instantly from your console.
- Rate limiting and throttling on authentication and other sensitive operations.
- Least-privilege database roles; every remote procedure authorises the caller rather than trusting the client.
- An immutable audit log of administrative actions.
- Automated backups, with restores exercised and verified.
- A nightly end-to-end suite against the live platform, including an adversarial pass that attempts tenant-isolation breaches, privilege escalation and injection.
We may change these measures, provided the level of protection is not reduced.
6. Your obligations as controller
You are responsible for:
- having a lawful basis for the personal data you collect through Menew;
- telling your diners how you handle their data — your own privacy notice, displayed where they can find it. Ours describes what the platform does; it does not describe what you do with the data afterwards;
- the accuracy of what you enter, including allergen tags;
- configuring the platform appropriately — which staff hold which permissions, who can see order history, who can issue refunds;
- not entering special category data into free-text fields. Order notes, reservation notes and staff names are ordinary text fields and are not designed to hold health, religious or biometric data. If a diner tells you about an allergy, that is health data, and putting it in a free-text note makes you responsible for it.
7. Sub-processors
You give us general authorisation to engage sub-processors. Our current list is maintained in the Privacy Policy and is, at the effective date of this document:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | EU — Frankfurt |
| Vercel | Hosting and content delivery | Global edge |
| Resend | Transactional email | EU / US |
| Anthropic | Optional AI assistance on menu text only | US |
| Google (Apps Script) | Optional Sheets sync, only if you configure one | Global |
We will give you at least 30 days' notice before adding or replacing a sub-processor that processes personal data. If you reasonably object on data-protection grounds within that period, we will work with you to find an alternative; if we cannot, you may terminate the affected part of the service without penalty and receive a refund of the unused prepaid portion.
We remain responsible to you for what our sub-processors do.
8. International transfers
Personal data is stored in the European Union. Where a sub-processor processes data outside the EU, that transfer is covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard.
9. Helping you answer data subjects
If a diner or a member of your staff contacts us directly with a request about their data, we will not answer it ourselves — we will refer them to you and tell you promptly.
We will give you reasonable assistance in answering access, correction, deletion, objection, restriction and portability requests, using the tools in your console where they cover it. Where they do not, write to support@menew.io and we will help.
We will also give you reasonable assistance with data-protection impact assessments and with consultations with a supervisory authority, so far as they relate to Menew.
10. Breach notification
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 72 hours, with:
- what happened, and when, so far as we know it;
- which categories of data and roughly how many records are affected;
- the likely consequences;
- what we have done and are doing about it.
We will not wait until we have a complete picture to tell you. Notifying the supervisory authority and the affected individuals is your decision as controller; we will give you what you need to make it.
11. Audit and information
On reasonable written request, and no more than once a year unless a breach or a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate our compliance with this document.
We are a small company. An on-site audit is available where a supervisory authority requires one, at your cost, on 30 days' notice, subject to confidentiality, and arranged so as not to disrupt the platform or expose another customer's data.
12. Return and deletion
You can export your data from your console at any time while your subscription is active.
On termination, and if you ask within 30 days, we will provide a machine-readable export at no charge. After that window we delete your personal data from live systems.
Backups. Deletion is applied to live data immediately. Backups containing the data expire on their own rolling cycle rather than being individually edited — editing a backup would defeat what a backup is for. Data in an expiring backup is not accessed or used for anything, and expires in the ordinary course.
We may keep data where a law requires it — billing records for tax purposes, for example — and only for as long as it requires.
13. Liability
The limitation of liability in section 12 of the Terms of Service applies to this document, except where applicable data-protection law does not permit it.
14. Changes
We may update this document to reflect a change in law or in how the platform works. Material changes come with at least 30 days' notice by email. Every version carries a version number and an effective date.
If your own data-protection obligations require a signed agreement, or your counsel needs changes to this text, write to support@menew.io. We would rather negotiate it than have you sign something that does not fit.